DPDS Unit 1: Complete Concept Guide
Unit 1: Introduction to Data Security -> Generated and Prepared By Thiruselvan (ThiruXD)
TABLE OF CONENT
PART 1: INTRODUCTION TO DATA SECURITY
- 1.1 Evolution of Data Security
- Historical Timeline (1950s-1980s → 1990s → Today)
- 1.2 Why Data Security Matters Today
- Financial Impact
- Cybercrime Damages
- Scale of Exposure
- Human Factor
- 1.3 Security as a Multidimensional Problem
- Governance, Legal, Ethical, and Business Continuity Dimensions
- Consequences of Security Failures
PART 2: INFORMATION SECURITY PRINCIPLES
- 2.1 The CIA Triad
- Confidentiality (C)
- Integrity (I)
- Availability (A)
- 2.2 Extended Security Principles
- Authentication
- Authorization
- Non-Repudiation
- Accountability
- Privacy
- Authenticity
- Resilience
- Least Privilege
PART 3: SECURITY FRAMEWORKS
- 3.1 AAA Framework
- Authentication (Who are you?)
- Authorization (What can you do?)
- Accounting/Auditing (What did you do?)
- 3.2 Defense in Depth: Layered Security
- Layer 1: Physical Security
- Layer 2: Perimeter Security
- Layer 3: Network Security
- Layer 4: Endpoint Security
- Layer 5: Application Security
- Layer 6: Data Security
- Layer 7: User and Identity
- Layer 8: Administrative Controls
PART 4: SECURITY POLICIES
- 4.1 Enterprise Security Policy (ESP)
- Definition
- Why Organizations Need Security Policies
- 4.2 Core Elements of Security Policy
- Purpose Statement
- Scope
- Policy Statements
- Roles and Responsibilities
- Compliance and Enforcement
- Exceptions Process
- Review and Update Schedule
- Definitions
- References
- Approval and Signatures
- 4.3 Security Policy Types
- Acceptable Use Policy (AUP)
- Information Classification Policy
- Access Control Policy
- Password Policy
- Remote Access Policy
- Incident Response Policy
- Data Retention and Disposal Policy
- Third-Party/Vendor Security Policy
- Bring Your Own Device (BYOD) Policy
- Physical Security Policy
- 4.4 The Policy Lifecycle
- Draft → Review → Approval → Publish and Communicate → Enforce and Monitor → Review and Update → Retire
- 4.5 Policy Taxonomy
- Four-Level Security Documentation Hierarchy
- L1: Policies (The Authority Layer)
- L2: Standards (The Specification Layer)
- L3: Procedures (The Operational Layer)
- L4: Guidelines (The Recommendation Layer)
- Four-Level Security Documentation Hierarchy
- 4.6 Additional Policy Taxonomy Categories
- Regulatory Policies
- Advisory Policies
- Informative Policies
- Technical Policies
- Operational Policies
PART 5: DATA BREACH
- 5.1 Definition
- 5.2 Cyber Kill Chain Framework
- Stage 1: Reconnaissance
- Stage 2: Weaponization
- Stage 3: Delivery
- Stage 4: Exploitation
- Stage 5: Installation
- Stage 6: Command & Control (C2)
- Stage 7: Actions on Objectives
- 5.3 Attack Vectors
- Phishing / Social Engineering
- Stolen/Compromised Credentials
- Vulnerabilities/Exploits
- Insider Threats
- Third-Party/Supply Chain
- Physical Access
PART 6: DATA REMANENCE
- 6.1 Definition
- Why Deleted Data is Not Gone
- Formatting Does NOT Destroy Data
- 6.2 Data Remanence Categories
- Magnetic Remanence
- Flash Remanence
- RAM Remanence (Cold Boot Attack)
- Cloud and Virtualized Storage
- Backup and Archive Copies
- File System Artifacts
- 6.3 Data Destruction Standards
- Sanitization Methods
- Clearing
- Purging
- Destroying
- Sanitization Methods
PART 7: DATA THEFT
- 7.1 Definition
- 7.2 Data Theft Categories
- External Cyber Attacks
- Insider Theft (Malicious)
- Insider Negligence
- Physical Theft
- Corporate Espionage
- 7.3 Data Loss Prevention (DLP)
- DLP Data States
- Data in Use
- Data in Motion
- Data at Rest
- DLP Enforcement Actions
- DLP Data States
- 7.4 Data Theft Prevention Controls
- Access Control
- Data Classification
- Encryption
- Endpoint Security
- Network Controls
- User Behavior Analytics (UEBA)
- Physical Security
- Employee Lifecycle Management
- Security Awareness
- Monitoring and Auditing
PART 8: WIRELESS IDENTITY THEFT
- 8.1 Definition
- Technologies at Risk
- Common Objectives
- 8.2 Types of Wireless Identity Theft
- RFID Attacks
- NFC Attacks
- Wi-Fi Attacks
- Bluetooth Attacks
- Mobile Attacks
- IoT Attacks
- Real-World Impact
- 8.3 RFID & NFC Vulnerabilities
- RFID Risks
- NFC Risks
- 8.4 Specific Attack Techniques
- Man-in-the-Middle (MITM)
- Evil Twin Attack
- Other Techniques
PART 9: KEY TAKEAWAYS
- Summary Checklist
PART 10: COMPLIANCE REFERENCES
- Key Regulations
- GDPR
- HIPAA
- CCPA
- PCI DSS
- SOX
PART 1: INTRODUCTION TO DATA SECURITY
1.1 Evolution of Data Security
Historical Timeline
| Period | Focus | Characteristics |
|---|---|---|
| 1950s-1980s | Physical Security | Protection of hardware; mainframes in locked rooms |
| 1990s | Perimeter Security | Firewalls, intrusion detection, antivirus; rise of networked systems |
| Today | Embedded Security | Cloud computing, mobile devices, IoT, big data; security integrated into every layer |
Why Data Security Matters Today
- Financial Impact: Average global cost of data breach = USD 4.45 million (IBM 2023)
- Cybercrime Damages: Projected USD 10.5 trillion annually (2025)
- Scale of Exposure: Over 6 billion records exposed in 2021 alone
- Human Factor: Approximately 82% of breaches involve human error (Verizon DBIR 2023)
Security as a Multidimensional Problem
Security is NOT purely a technical problem — it is a governance, legal, ethical, and business continuity problem
Consequences of Security Failures:
- Financial penalties
- Reputational damage
- Loss of customer trust
- Regulatory fines
- In critical sectors (healthcare, energy): can endanger lives
PART 2: INFORMATION SECURITY PRINCIPLES
2.1 The CIA Triad
The foundational model for information security policy development and risk analysis.
| Principle | Definition | Mechanisms |
|---|---|---|
| Confidentiality (C) | Ensuring information is accessible ONLY to those authorized to access it | • Encryption• Access Control• Data Classification• Steganography |
| Integrity (I) | Safeguarding accuracy and completeness of information and processing methods | • Cryptographic Hashing• Digital Signatures• MACs (Message Authentication Codes)• Version Control & Audit Trails• File Integrity Monitoring (FIM) |
| Availability (A) | Ensuring authorized users have reliable access to information and systems when needed | • Redundancy & Failover• Load Balancing• Backups & Disaster Recovery• DDoS Mitigation• Uptime SLAs |
2.2 Extended Security Principles
| Principle | Description | Significance |
|---|---|---|
| Authentication | Verifying identity of users, systems, or processes | Methods: passwords, MFA, biometrics, PKI certificates. Prevents unauthorized access by imposters |
| Authorization | Determining what an authenticated user is permitted to do | Enforced via RBAC, ABAC (Attribute-Based Access Control), access control lists |
| Non-Repudiation | Ensuring a party cannot deny having performed an action | Achieved through digital signatures and audit logs. Critical in legal and financial contexts |
| Accountability | Holding individuals responsible for their actions | Maintaining detailed audit trails. Logs must be tamper-proof and time-stamped |
| Privacy | The right of individuals to control how their personal data is collected and used | Governed by regulations (GDPR, HIPAA). Goes beyond security into ethics and law |
| Authenticity | Confirming data comes from a genuine, trusted source | Enforced via digital certificates and signature verification |
| Resilience | Ability of a system to withstand attacks and continue operating in a degraded but functional state | Goes beyond recovery to proactive fault tolerance |
| Least Privilege | Users and systems should have the minimum level of access required to perform their functions | Limits the damage any compromised account can cause |
PART 3: SECURITY FRAMEWORKS
3.1 AAA Framework
Authentication, Authorization, Accounting
🔐 Authentication (Who are you?)
Verifying identity through Multi-Factor Authentication (MFA) :
| Factor Type | Examples |
|---|---|
| Something you know | Password, PIN |
| Something you have | Hardware token, smart card |
| Something you are | Biometric: fingerprint, iris scan, facial recognition |
🔑 Authorization (What can you do?)
After authentication, a policy engine checks:
- What resources the authenticated user is allowed to access
- What actions they can perform
📝 Accounting/Auditing (What did you do?)
- Every login attempt, file access, configuration change, and network connection is logged
- Audit logs = foundation of forensics and compliance
3.2 Defense in Depth: Layered Security
“Implement multiple layers of control - Even if one layer fails, others still protect the system”
| Layer | Controls |
|---|---|
| Layer 1: Physical Security | Fences, security guards, CCTV, biometric door locks, server room access controls |
| Layer 2: Perimeter Security | Firewalls, IDS/IPS, DMZ architecture |
| Layer 3: Network Security | VLANs, network segmentation, encrypted protocols (TLS, IPSec, SSH) |
| Layer 4: Endpoint Security | Antivirus, EDR, host-based firewalls, disk encryption |
| Layer 5: Application Security | Secure coding practices, WAF, input validation, API security |
| Layer 6: Data Security | Encryption at rest and in transit, DLP, data classification, rights management |
| Layer 7: User and Identity | MFA, SSO, PAM, security awareness training |
| Layer 8: Administrative Controls | Security policies, procedures, audits, incident response plans |
PART 4: SECURITY POLICIES
4.1 Enterprise Security Policy (ESP)
Definition: A formal, management-approved document that defines an organization’s approach to protecting its information assets.
The highest-level security document that provides the foundation for all other security documents (standards, procedures, guidelines)
Why Organizations Need Security Policies?
| Reason | Explanation |
|---|---|
| Legal and Regulatory Compliance | Laws such as GDPR, HIPAA, and CCPA require documented security practices. Without policies, compliance cannot be demonstrated |
| Consistency | Ensure all employees, contractors, and vendors handle data consistently, reducing human-error breaches |
| Accountability | Establish clear responsibilities so in the event of a breach, it’s clear who was responsible for which control |
| Risk Management | Mechanism by which management formally accepts, mitigates, transfers, or avoids risk |
| Security Culture | Well-communicated policies build a culture of security awareness across the organization |
4.2 Core Elements of Security Policy
| Policy Element | Description |
|---|---|
| Purpose Statement | Why does this policy exist? What risk or compliance requirement does it address? |
| Scope | Who and what does the policy apply to? (All employees, contractors, vendors; all systems, or specific data types?) |
| Policy Statements | The specific rules, requirements, and prohibitions. Written in clear, unambiguous language |
| Roles and Responsibilities | Who is responsible for enforcing the policy? (CISO, IT Security team, system owners, employees) |
| Compliance and Enforcement | What are the consequences of non-compliance? (Disciplinary action, termination, legal prosecution) |
| Exceptions Process | How can exceptions to the policy be requested and approved? |
| Review and Update Schedule | How frequently is the policy reviewed? (Typically annually, or after a significant security event) |
| Definitions | Clear definitions of technical terms used in the policy |
| References | Related policies, standards, laws, and regulations that this policy is aligned with |
| Approval and Signatures | Management approval (typically CISO, CIO, or CEO sign-off) gives the policy authority |
4.3 Security Policy Types
| Policy Type | Coverage |
|---|---|
| Acceptable Use Policy (AUP) | Rules for acceptable and prohibited use of company systems, email, internet, and devices |
| Information Classification Policy | Framework for classifying data by sensitivity (Public, Internal, Confidential, Restricted) and handling rules for each |
| Access Control Policy | Rules for granting, managing, reviewing, and revoking access to systems and data |
| Password Policy | Minimum password length, complexity, expiry, reuse, and multi-factor authentication requirements |
| Remote Access Policy | Requirements for VPN usage, endpoint security for remote workers, and split tunneling rules |
| Incident Response Policy | Procedures for detecting, reporting, containing, investigating, and recovering from security incidents |
| Data Retention and Disposal Policy | How long data must be kept, how it must be securely deleted, and what destruction standards apply |
| Third-Party/Vendor Security Policy | Security requirements that vendors and partners must meet to access organizational data or systems |
| Bring Your Own Device (BYOD) Policy | Rules for using personal devices for work, including MDM enrollment, encryption, and remote wipe capability |
| Physical Security Policy | Controls for physical access to facilities, server rooms, and equipment |
4.4 The Policy Lifecycle
A security policy is not a static document - Follows a lifecycle:
- Draft: Security team drafts the policy based on risk assessment and compliance requirements
- Review: Legal, HR, IT, and business unit stakeholders review the draft
- Approval: Executive management (CISO/CIO/CEO) formally approves the policy
- Publish and Communicate: Policy is distributed to all affected parties. Training is conducted
- Enforce and Monitor: Compliance is monitored through audits, technical controls, and user reporting
- Review and Update: Policy is reviewed at scheduled intervals and updated when threats, technology, or regulations change
- Retire: Policies that are no longer relevant are formally retired and replaced
4.5 Policy Taxonomy
Definition: Systematic classification and organization of security documents into a coherent hierarchy.
A well-defined taxonomy ensures that every security requirement is documented at the appropriate level of detail and authority. There are no gaps or contradictions between documents.
Four-Level Security Documentation Hierarchy
| Level | Document Type | Characteristics | Example |
|---|---|---|---|
| L1 | POLICIES | Highest authority, management-approved, broad and general. State what MUST be done. Rarely change. | “All data at rest must be encrypted” |
| L2 | STANDARDS | More specific than policies, define measurable requirements. State HOW MUCH or HOW WELL. | “Encryption must use AES-256 or higher” |
| L3 | PROCEDURES | Step-by-step instructions for implementing a policy or standard. Operational, detailed, role-specific. | “Step 1: Install BitLocker. Step 2: Enable AES-256…” |
| L4 | GUIDELINES | Recommended (not mandatory) best practices. Provide flexibility. | “It is recommended to store encryption keys in a separate HSM” |
Standards: The Specification Layer
- Translate policy intent into specific, measurable requirements
- Define minimum acceptable security configurations, algorithms, key length protocols
- Mandatory and specific, but less frequent in change than procedures
- Reference to external standards (ISO 27001, NIST SP 800-53, PCI DSS)
- Written for a technical audience and contain technical specifications
Example Standard Statement:
“Encryption of data at rest on portable devices must use AES-256 in CBC or GCM mode. Key management must use FIPS 140-2 validated hardware security modules (HSMs). Encryption keys must be rotated every 12 months.”
Policies: The Authority Layer
- The strategic layer of security documentation
- Express management’s intent and commitment to security
- Written in simple, non-technical language accessible to all employees
- Have long lifespans (years) and change only when business strategy or regulatory environment changes significantly
- Typically 1-5 pages in length — concise and broad
- Carry the weight of organizational authority — violation can result in disciplinary action
Example Policy Statement:
“All company data classified as Confidential or Restricted must be encrypted using approved algorithms when stored on any portable device.”
Procedures: The Operational Layer
- Day-to-day operational instructions that tell employees exactly how to perform security-related tasks
- Step-by-step, sequential, and role-specific
- Include who does what, when, and with which tools
- Change frequently as technology and processes evolve
- Primary document used during audits and compliance reviews to demonstrate implementation
Example: Patch Management Procedure:
- Monitor vendor security advisories daily
- Classify patches as Critical / High / Medium / Low
- Test Critical patches in the staging environment within 24 hours
- Deploy Critical patches to production within 72 hours
- Document patching in the ITSM ticketing system
- Verify patch success and update asset inventory
Guidelines: The Recommendation Layer
- Non-mandatory recommendations that help employees make good security decisions
- Provide flexibility in implementation while still promoting best practices
- Particularly useful in areas that are rapidly evolving (e.g., AI/ML security)
- Cannot be used as the basis for disciplinary action if not followed
Example:
“It is recommended that employees use a password manager to generate and store complex, unique passwords for each service, rather than creating passwords manually.”
4.6 Additional Policy Taxonomy Categories
| Category | Description |
|---|---|
| Regulatory Policies | Derived from legal requirements (GDPR, HIPAA, SOX). Mandatory compliance; non-compliance results in regulatory penalties |
| Advisory Policies | Strongly recommended practices that, while not mandatory, are expected to be followed in most circumstances |
| Informative Policies | Educational in nature; designed to inform employees about security risks and best practices without mandating specific actions |
| Technical Policies | Govern specific technical controls (e.g., firewall configuration policy, cryptography policy, software development lifecycle policy) |
| Operational Policies | Govern day-to-day security operations (e.g., incident response policy, change management policy, log review policy) |
PART 5: DATA BREACH
5.1 Definition
Data Breach: An incident in which unauthorized individuals gain access to sensitive, protected, or confidential data, potentially exposing it to unauthorized parties.
Key Insight: Most significant data breaches are not instantaneous events — they are deliberate campaigns that unfold over days, weeks, or even months.
5.2 Cyber Kill Chain Framework
Developed by Lockheed Martin - 7 Stages of a Data Breach
| Stage | Attacker Activity | Defensive Opportunity |
|---|---|---|
| 1. Reconnaissance | Attacker gathers information about the target: employee names, email formats, IP ranges, technologies in use, social media profiles, job postings (which reveal technologies used). Tools: OSINT (Maltego, Shodan), LinkedIn, Google Dorking | Minimize public exposure, monitor for scanning activity, employee awareness of social engineering |
| 2. Weaponization | Attacker creates or acquires a weapon: malware payload (ransomware, RAT, keylogger), exploit code for a known vulnerability, phishing email template | Patch known vulnerabilities promptly (reducing exploitable attack surface), use email security gateways to filter malicious attachments |
| 3. Delivery | Attacker delivers the weapon to the target: phishing email with malicious attachment or link, drive-by download via compromised website, USB drop, supply chain compromise | Email filtering, web proxies, user awareness training, endpoint protection |
| 4. Exploitation | The weapon executes: user clicks phishing link and malware runs, browser exploit fires, SQL injection extracts credentials | Patch management, application whitelisting, EDR, secure coding |
| 5. Installation | Attacker establishes persistence: installs backdoor, creates rogue admin account, modifies startup scripts, injects into legitimate processes | File integrity monitoring, privileged access management, behavioral analytics (UEBA) |
| 6. Command & Control (C2) | Attacker communicates with the compromised system: establishes encrypted C2 channel (often using legitimate protocols like HTTPS, DNS to blend in), receives instructions, downloads additional tools | Network traffic analysis, DNS monitoring, proxy inspection of HTTPS traffic |
| 7. Actions on Objectives | Attacker achieves their goal: exfiltrates sensitive data, deploys ransomware, destroys data, pivots to other systems, establishes long-term presence | DLP, network segmentation, data classification, anomaly detection for large outbound data transfers |
5.3 Attack Vectors
Understanding the primary vectors through which breaches are initiated allows organizations to prioritize defensive investments.
| Attack Vector | Frequency / Examples | Defenses |
|---|---|---|
| Phishing / Social Engineering | 31% of breaches (Verizon DBIR 2023). Spear phishing, BEC (Business Email Compromise), vishing (voice phishing), smishing (SMS phishing) | Email security, DMARC/SPF/DKIM, security awareness training, phishing simulations |
| Stolen/Compromised Credentials | 49% of breaches. Password reuse, credential stuffing, dark web credential purchases | MFA, Password Manager, PAM, monitoring dark web for exposed credentials |
| Vulnerabilities/Exploits | 26% of breaches. Unpatched systems, zero-day exploits, misconfigured cloud services | Patch management, vulnerability scanning, security configuration management |
| Insider Threats | 19% of breaches (Ponemon 2022). Malicious insiders (data theft, sabotage), negligent insiders (mistakes, policy violations), compromised insiders (credential theft) | Least privilege, UEBA, DLP, background checks |
| Third-Party/Supply Chain | Growing vector - 62% of network intrusions via partner exploitation. Software supply chain (SolarWinds, Log4Shell). Service provider access abuse | Third-party risk management, vendor security assessments, supply chain transparency |
| Physical Access | Often underestimated. Stolen laptops/devices, tailgating into secure areas, dumpster diving, evil maid attacks | Full disk encryption, physical security controls, clean desk policy |
PART 6: DATA REMANENCE
6.1 Definition
Data Remanence: Residual representation of digital data that persists on a storage medium after attempts to erase or delete it.
Critical Insight: ‘Deleted’ data is frequently recoverable using forensic techniques — posing a significant security risk when storage media is repurposed, donated, sold, or disposed of.
Why Deleted Data is Not Gone?
When a file is ‘deleted’ in most operating systems:
- The operating system removes the directory entry (file name and metadata are removed from the file system table)
- Marks the storage blocks previously occupied by the file as ‘available’ for future use
- Actual data remains physically on the disk until those blocks are overwritten by new data
Freely available tools (Recuva, TestDisk, PhotoRec, FTK, EnCase), forensic investigators — or attackers — can recover this ‘deleted’ data trivially.
Formatting Does NOT Destroy Data
| Format Type | What It Does | Data Destruction Level |
|---|---|---|
| Quick Format | Rewrites the file system structure | Minimal - Data easily recoverable |
| Full Format | Overwrites each sector with zeros | More thorough, but may still leave traces recoverable by advanced laboratory techniques |
6.2 Data Remanence Categories
Magnetic Remanence
- Laboratory tools can read a “magnetic shadow” of overwritten data on old hard drives
- Modern high-density drives make this recovery almost impossible in practice
- While technically a risk, it is highly impractical on modern hardware
Flash Remanence
- SSDs move data around to extend the drive’s lifespan
- Overwriting a specific file leaves the old data hidden in spare storage cells
- Traditional file deletion and overwriting do not completely wipe SSDs
RAM Remanence (Cold Boot Attack)
- Freezing DRAM with liquid nitrogen keeps data active for minutes after power-off
- Attackers with physical access can extract encryption keys and passwords
- Proven, real-world attack technique, not just a theory
Cloud and Virtualized Storage
- New tenants can access leftover data from previous users
- Poor storage wiping during user reallocation
- Providers use encryption and data overwriting to block access
Backup and Archive Copies
- Deleted files often live on in backup tapes and archive systems
- Strict retention policies are missing or not properly enforced
- Automated deletion rules must target every single backup copy
File System Artifacts
File system journals, log files, swap files, print spoolers, browser cache, and system restore points may contain fragments of ‘deleted’ data.
6.3 Data Destruction Standards
Purpose: Provide organizations with authoritative, recognized methods for permanently removing sensitive data from storage media at end-of-life.
Essential for Compliance:
- GDPR Article 17 — Right to Erasure
- HIPAA safeguards
- PCI DSS Requirement 9.8.2
- Preventing data remanence exploits
Sanitization Methods
| Sanitization Method | Description | Applicable When |
|---|---|---|
| Clearing | Overwrites data with zeros using standard software commands | Internal reuse - Media stays inside the organization |
| Purging | Block lab level recovery via secure erase, crypto-erase, or degaussing | External release - Media is being sold, donated, or traded in |
| Destroying | Physically shreds, melts, or incinerates the storage media | Classified data - End-of-life media leaving company custody |
PART 7: DATA THEFT
7.1 Definition
Data Theft: Unauthorized taking, copying, or transfer of confidential, sensitive, or proprietary information from an organization or individual.
Key Insight: Unlike traditional theft, data theft often leaves the original data intact — making it difficult to detect.
Perpetrators may be:
- External attacker
- Malicious insider
- Business competitor engaged in corporate espionage
7.2 Data Theft Categories
| Category | Description | Examples |
|---|---|---|
| External Cyber Attacks | Remote attackers exploiting vulnerabilities, stolen credentials, malware, ransomware, or supply chain compromise to exfiltrate data | APT groups, ransomware gangs, hacktivist groups |
| Insider Theft (Malicious) | Employees, contractors, or privileged users deliberately stealing data for financial gain, competitive advantage, espionage, or revenge | A departing employee exfiltrating customer database to a competitor |
| Insider Negligence | Employees accidentally exposing data through misconfiguration, sending data to wrong recipients, using unapproved cloud services (Shadow IT), or losing devices | The majority of ‘insider incidents’ are negligent rather than malicious |
| Physical Theft | Stealing physical devices (laptops, smartphones, USB drives, printed documents) that contain unencrypted sensitive data | A laptop stolen from an airport lounge containing unencrypted patient records |
| Corporate Espionage | Competitors or nation-state actors systematically stealing intellectual property, trade secrets, research data, or strategic plans | Involves sophisticated, long-duration campaigns |
7.3 Data Loss Prevention (DLP)
The Primary Technical Defense
Definition: Set of tools and processes that monitor, detect, and block unauthorized movement of sensitive data.
DLP Data States
| Data State | How DLP Protects |
|---|---|
| Data in Use | DLP agent monitors clipboard operations, print jobs, screenshot attempts, and USB data transfers on endpoint devices |
| Data in Motion | DLP proxy or email gateway inspects network traffic (email, web uploads, FTP) for sensitive content (credit card numbers, SSNs, health records) using content inspection |
| Data at Rest | DLP discovers and classifies sensitive data stored in file servers, databases, cloud storage, and endpoints, flagging improperly stored sensitive data |
DLP Enforcement Actions
- Alert
- Block
- Quarantine
- Encrypt
- User Notification
- Require Justification
7.4 Data Theft Prevention Controls
| Control Category | Specific Controls |
|---|---|
| Access Control | Least-privilege access model. Role-Based Access Control (RBAC). Privileged Access Management (PAM). Just-In-Time access. Regular access reviews and certification |
| Data Classification | Classify all data by sensitivity. Apply handling requirements per classification. Use automated classification tools (Microsoft Purview, Varonis) |
| Encryption | Encrypt all sensitive data at rest and in transit. Full disk encryption on all endpoints. Rights Management (IRM/DRM) for document-level protection |
| Endpoint Security | DLP agent on all endpoints. USB port control (block or allow list). Application whitelisting. Endpoint Detection and Response (EDR) |
| Network Controls | Email DLP gateway. Web proxy with HTTPS inspection. Firewall rules blocking unauthorized outbound connections. Network traffic analysis (NTA) |
| User Behavior Analytics (UEBA) | Baseline normal user behavior. Alert on anomalies: bulk data downloads, access at unusual hours, access to unusual data, large file uploads to external sites |
| Physical Security | Full-disk encryption for all portable devices. Remote wipe capability for lost/stolen devices. Clean desk policy. Screen privacy filters in public areas |
| Employee Lifecycle Management | Revoke all access on employee termination (same-day, automated). Conduct exit interviews. Monitor departing employees for unusual data access in final weeks |
| Security Awareness | Train employees on insider threat recognition. Create a security-positive culture where employees report suspicious behavior. Implement anonymous whistleblower channels |
| Monitoring and Auditing | Log all access to sensitive data. Retain logs in tamper-proof storage. Regular log review and alerting. Periodic security audits and penetration testing |
PART 8: WIRELESS IDENTITY THEFT
8.1 Definition
Wireless Identity Theft: Unauthorized theft of personal or financial information through wireless communication technologies.
Exploits radio-frequency (RF) communication without physical contact
Technologies at Risk
- RFID cards
- NFC payments
- Wi-Fi networks
- Bluetooth devices
- IoT devices
Common Objectives
- Identity theft
- Financial fraud
- Account takeover
- Unauthorized access
8.2 Types of Wireless Identity Theft
| Technology | Common Attack | Example |
|---|---|---|
| RFID | Skimming, Cloning | Reading contactless cards |
| NFC | Malicious NFC tags | Fake payment requests |
| Wi-Fi | Evil Twin, MITM | Fake public Wi-Fi hotspot |
| Bluetooth | Bluesnarfing, Bluebugging | Stealing contacts/messages |
| Mobile | SIM Swapping | Bypassing SMS OTP |
| IoT | Data interception | Smart wearable information theft |
Real-World Impact
- Millions of identity theft cases annually
- Rising contactless payment fraud
- Increasing SIM swapping attacks targeting online banking and cryptocurrency
8.3 RFID & NFC Vulnerabilities
RFID Risks
- Eavesdropping
- Skimming
- Relay attacks
- Card cloning
- Data modification
- Signal jamming
NFC Risks
- Rogue NFC applications
- Malicious NFC tags
- Data corruption
- Relay attacks
- NFC phishing
Strong encryption and secure key management are essential
8.4 Specific Attack Techniques
Man-in-the-Middle (MITM)
- Attacker secretly intercepts communication between two parties
- Examples: SSL Stripping, ARP Poisoning, DNS Spoofing, HTTPS Spoofing, BGP Hijacking
Evil Twin Attack
- Create fake Wi-Fi hotspot
- Victim connects
- Traffic passes through attacker
- Credentials are stolen
Other Techniques
- Wi-Fi sniffing
- IMSI Catchers (Fake cell towers)
- Bluetooth sniffing
- SIM Swapping
PART 9: KEY TAKEAWAYS
Summary Checklist
| Concept | Key Points |
|---|---|
| CIA Triad | Confidentiality, Integrity, Availability - Foundational security model |
| Extended Principles | Authentication, Authorization, Non-Repudiation, Accountability, Privacy, Authenticity, Resilience, Least Privilege |
| AAA Framework | Authentication (Who), Authorization (What), Accounting/Auditing (What did they do?) |
| Defense in Depth | 8 layers: Physical → Perimeter → Network → Endpoint → Application → Data → User/Identity → Administrative |
| Security Policies | Enterprise Security Policy (ESP), Policy lifecycle, 4-level taxonomy |
| Policy Taxonomy | Policies (L1) → Standards (L2) → Procedures (L3) → Guidelines (L4) |
| Data Breach | Cyber Kill Chain: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions on Objectives |
| Attack Vectors | Phishing, Credentials, Vulnerabilities, Insider Threats, Supply Chain, Physical |
| Data Remanence | Residual data persists after deletion. Sanitization: Clearing, Purging, Destroying |
| Data Theft | External attacks, Malicious insiders, Negligence, Physical theft, Espionage |
| DLP | Protects Data in Use, Data in Motion, Data at Rest |
| Wireless Identity Theft | RFID, NFC, Wi-Fi, Bluetooth, Mobile, IoT attacks |
PART 10: COMPLIANCE REFERENCES
Key Regulations
| Regulation | Relevance |
|---|---|
| GDPR | Data protection, right to erasure, privacy |
| HIPAA | Healthcare data protection |
| CCPA | California consumer privacy |
| PCI DSS | Payment card data security |
| SOX | Financial data integrity |